home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1956
Discussions: 188,470, Posts: 2,244,183, Members: 232,725
Old March 14th, 2004, 08:38 PM   Digg it!   #1 (permalink)
Ultimate Member
 
Richard Cranium's Avatar
 
Join Date: Oct 2001
Location: Dahlonega Ga
Posts: 8,105
OLJZA5ZE3C.Exe Virus/Worm Help Needed

Got a customer unit with a self replicating .exe in the startup menu.

The location of the .exe is bogus, listed as C:Windows\OLJZA5ZE3C.Exe

The Name listed in MSCONFIG is random numbers and letters 7-10 digits long.

It's listed over a hundred times, going into SAFE Mode don't help.

Taking any action in Windows normal is out of the question with the system at 100% CPU usage from the rascal.

Running a Norton Corporate floppy which scanned in DOS for 4 hrs & 11 Minutes gave no joy, "No Viruses" found.

Beside Format C: any ideas.

TIA
Doc

Richard Cranium is offline   Reply With Quote
Old March 15th, 2004, 11:13 AM     #2 (permalink)
Ultimate Member
 
Richard Cranium's Avatar
 
Join Date: Oct 2001
Location: Dahlonega Ga
Posts: 8,105
Bumpage

Richard Cranium is offline   Reply With Quote
Old March 15th, 2004, 11:25 AM     #3 (permalink)
Member
 
Zotzmein's Avatar
 
Join Date: Oct 2001
Location: Tulsa, OK. *USA*
Posts: 462
Send a message via AIM to Zotzmein Send a message via Yahoo to Zotzmein
Two Cents

I maybe showing my ignorance here, I’m no experienced virus hunter but could you slave the unit to an isolated machine, boot to your primary and attack it from that point?

My theory being that the virus replicates itself in the active operating system when booted, if that drive is not booted to then the virus doesn’t spread. Then maybe you could pick out and destroy the various iterations of the virus or perhaps use a more robust anti-viral program than was on your diskette, just some random thoughts on the subject.

Regards,
Zotz Mein

Zotzmein is offline   Reply With Quote
Old March 15th, 2004, 12:30 PM     #4 (permalink)
Banned
 
thronka's Avatar
 
Join Date: Dec 2002
Location: Garland, Texas USA
Posts: 1,785
Does this virus close your virus window while botted into windows? I (well a customer) had a virus simular named and every time I loaded to trans macros house call it closed it . It even removed Norton. It was weird. I suspected the kid downloaded loads of stuff on it. I tried everything, but ended up reloading the whole system as a last resort. There is a fix now, but I don't know where.
thronka is offline   Reply With Quote
Old March 15th, 2004, 12:56 PM     #5 (permalink)
Supporting our military
 
Bill in SD, CA's Avatar
 
Join Date: Oct 2002
Location: Bottom left of U.S.
Posts: 9,194
The Cleaner perhaps?

For trojans but it got rid of things Norton couldn't for me.

Bill
Bill in SD, CA is offline   Reply With Quote
Old March 15th, 2004, 12:59 PM     #6 (permalink)
Ultimate Member
 
paul9's Avatar
 
Join Date: Aug 2003
Location: Gateshead U.K.
Posts: 8,838
Send a message via MSN to paul9 Send a message via Yahoo to paul9
try using a linux live cd such as knoppix, the virus won't start when you boot into linux. also, empty out the windows/temp/ folder as it is a favourite place for viruses to sit whilst disguised as .tmp files.
__________________
No man's life, liberty, or property are safe while the legislature is in session. --Mark Twain (1866)
paul9 is offline   Reply With Quote
Old March 15th, 2004, 01:37 PM     #7 (permalink)
Ultimate Member
 
Richard Cranium's Avatar
 
Join Date: Oct 2001
Location: Dahlonega Ga
Posts: 8,105
I got the MSCONFIG option of "Load Devices interactively" or whatever it's called and can get into Winderz.

Will try the cleaner.

Thanks for the suggestions, will update progress.

Doc
Richard Cranium is offline   Reply With Quote
Old March 16th, 2004, 10:32 AM     #8 (permalink)
Ultimate Member
 
Richard Cranium's Avatar
 
Join Date: Oct 2001
Location: Dahlonega Ga
Posts: 8,105
The Cleaner would not run, two attempts to load, run, uninstall, defrag, reload still gave run failures.

I've now formatted the unit and am reloading all.

Thanks for the attempts.

Doc
Richard Cranium is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Most Active Discussions
Is It Just Me? (3002)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
AMD Phenom II X4 940 Black Edition (11)
nVidia GTX 295 now available (21)
Replacing integrated video card (5)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
I think I just killed my computer w.. (26)
Recent Discussions
WD Hard drive reading the wrong.. (1)
P4MAM2-V Mobo Support For Dual .. (1)
can't add picture to this forum (1)
NTVDM CPU has encountered an il.. (8)
canon eos20d problem (1)
I cant sign into msn messenger,.. (8)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 07:53 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28